You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/virtual-network/service-tags-overview.md
+35-35Lines changed: 35 additions & 35 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,90 +39,90 @@ By default, service tags reflect the ranges for the entire cloud. Some service t
39
39
40
40
| Tag | Purpose | Can use inbound or outbound? | Can be regional? | Can use with Azure Firewall? |
41
41
| --- | -------- |:---:|:---:|:---:|
42
-
|**ActionGroup**| Action Group. | Inbound | No |No|
42
+
|**ActionGroup**| Action Group. | Inbound | No |Yes|
43
43
|**ApiManagement**| Management traffic for Azure API Management-dedicated deployments. <br/><br/>**Note**: This tag represents the Azure API Management service endpoint for control plane per region. The tag enables customers to perform management operations on the APIs, Operations, Policies, NamedValues configured on the API Management service. | Inbound | Yes | Yes |
44
-
|**ApplicationInsightsAvailability**| Application Insights Availability. | Inbound | No |No|
45
-
|**AppConfiguration**| App Configuration. | Outbound | No |No|
44
+
|**ApplicationInsightsAvailability**| Application Insights Availability. | Inbound | No |Yes|
45
+
|**AppConfiguration**| App Configuration. | Outbound | No |Yes|
46
46
|**AppService**| Azure App Service. This tag is recommended for outbound security rules to web apps and Function apps.<br/><br/>**Note**: This tag doesn't include IP addresses assigned when using IP-based SSL (App-assigned address). | Outbound | Yes | Yes |
47
47
|**AppServiceManagement**| Management traffic for deployments dedicated to App Service Environment. | Both | No | Yes |
48
-
|**AutonomousDevelopmentPlatform**| Autonomous Development Platform | Both | Yes |No|
48
+
|**AutonomousDevelopmentPlatform**| Autonomous Development Platform | Both | Yes |Yes|
49
49
|**AzureActiveDirectory**| Azure Active Directory. | Outbound | No | Yes |
50
50
|**AzureActiveDirectoryDomainServices**| Management traffic for deployments dedicated to Azure Active Directory Domain Services. | Both | No | Yes |
51
-
|**AzureAdvancedThreatProtection**| Azure Advanced Threat Protection. | Outbound | No |No|
51
+
|**AzureAdvancedThreatProtection**| Azure Advanced Threat Protection. | Outbound | No |Yes|
52
52
|**AzureArcInfrastructure**| Azure Arc-enabled servers, Azure Arc-enabled Kubernetes, and Guest Configuration traffic.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory**,**AzureTrafficManager**, and **AzureResourceManager** tags. | Outbound | No | Yes |
53
53
|**AzureAttestation**| Azure Attestation. | Outbound | No | Yes |
54
54
|**AzureBackup**|Azure Backup.<br/><br/>**Note**: This tag has a dependency on the **Storage** and **AzureActiveDirectory** tags. | Outbound | No | Yes |
55
-
|**AzureBotService**| Azure Bot Service. | Outbound | No |No|
55
+
|**AzureBotService**| Azure Bot Service. | Outbound | No |Yes|
56
56
|**AzureCloud**| All [datacenter public IP addresses](https://www.microsoft.com/download/details.aspx?id=56519). | Both | Yes | Yes |
57
-
|**AzureCognitiveSearch**| Azure Cognitive Search. <br/><br/>This tag or the IP addresses covered by this tag can be used to grant indexers secure access to data sources. For more information about indexers, see [indexer connection documentation](../search/search-indexer-troubleshooting.md#connection-errors). <br/><br/> **Note**: The IP of the search service isn't included in the list of IP ranges for this service tag and **also needs to be added** to the IP firewall of data sources. | Inbound | No |No|
57
+
|**AzureCognitiveSearch**| Azure Cognitive Search. <br/><br/>This tag or the IP addresses covered by this tag can be used to grant indexers secure access to data sources. For more information about indexers, see [indexer connection documentation](../search/search-indexer-troubleshooting.md#connection-errors). <br/><br/> **Note**: The IP of the search service isn't included in the list of IP ranges for this service tag and **also needs to be added** to the IP firewall of data sources. | Inbound | No |Yes|
58
58
|**AzureConnectors**| This tag represents the IP addresses used for managed connectors that make inbound webhook callbacks to the Azure Logic Apps service and outbound calls to their respective services, for example, Azure Storage or Azure Event Hubs. | Both | Yes | Yes |
59
59
|**AzureContainerAppsService**| Azure Container Apps Service | Both | Yes | No |
|**AzureDigitalTwins**| Azure Digital Twins.<br/><br/>**Note**: This tag or the IP addresses covered by this tag can be used to restrict access to endpoints configured for event routes. | Inbound | No | Yes |
69
-
|**AzureEventGrid**| Azure Event Grid. | Both | No |No|
69
+
|**AzureEventGrid**| Azure Event Grid. | Both | No |Yes|
70
70
|**AzureFrontDoor.Frontend** <br/> **AzureFrontDoor.Backend** <br/> **AzureFrontDoor.FirstParty**| Azure Front Door. | Both | Yes | Yes |
71
71
|**AzureHealthcareAPIs**| The IP addresses covered by this tag can be used to restrict access to Azure Health Data Services. | Both | No | Yes |
72
-
|**AzureInformationProtection**| Azure Information Protection.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory**, **AzureFrontDoor.Frontend** and **AzureFrontDoor.FirstParty** tags. | Outbound | No |No|
|**AzureInformationProtection**| Azure Information Protection.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory**, **AzureFrontDoor.Frontend** and **AzureFrontDoor.FirstParty** tags. | Outbound | No |Yes|
|**AzureKeyVault**| Azure Key Vault.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory** tag. | Outbound | Yes | Yes |
75
75
|**AzureLoadBalancer**| The Azure infrastructure load balancer. The tag translates to the [virtual IP address of the host](./network-security-groups-overview.md#azure-platform-considerations) (168.63.129.16) where the Azure health probes originate. This only includes probe traffic, not real traffic to your backend resource. If you're not using Azure Load Balancer, you can override this rule. | Both | No | No |
76
76
|**AzureLoadTestingInstanceManagement**| This service tag is used for inbound connectivity from Azure Load Testing service to the load generation instances injected into your virtual network in the private load testing scenario. <br/><br/>**Note:** This tag is intended to be used in Azure Firewall, NSG, UDR and all other gateways for inbound connectivity. | Inbound | No | Yes |
77
77
|**AzureMachineLearning**| Azure Machine Learning. | Both | No | Yes |
78
78
|**AzureMonitor**| Log Analytics, Application Insights, AzMon, and custom metrics (GiG endpoints).<br/><br/>**Note**: For Log Analytics, the **Storage** tag is also required. If Linux agents are used, **GuestAndHybridManagement** tag is also required. | Outbound | No | Yes |
79
-
|**AzureOpenDatasets**| Azure Open Datasets.<br/><br/>**Note**: This tag has a dependency on the **AzureFrontDoor.Frontend** and **Storage** tag. | Outbound | No |No|
79
+
|**AzureOpenDatasets**| Azure Open Datasets.<br/><br/>**Note**: This tag has a dependency on the **AzureFrontDoor.Frontend** and **Storage** tag. | Outbound | No |Yes|
80
80
|**AzurePlatformDNS**| The basic infrastructure (default) DNS service.<br/><br/>You can use this tag to disable the default DNS. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](./network-security-groups-overview.md#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
81
81
|**AzurePlatformIMDS**| Azure Instance Metadata Service (IMDS), which is a basic infrastructure service.<br/><br/>You can use this tag to disable the default IMDS. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](./network-security-groups-overview.md#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
82
82
|**AzurePlatformLKM**| Windows licensing or key management service.<br/><br/>You can use this tag to disable the defaults for licensing. Be cautious when you use this tag. We recommend that you read [Azure platform considerations](./network-security-groups-overview.md#azure-platform-considerations). We also recommend that you perform testing before you use this tag. | Outbound | No | No |
83
-
|**AzureResourceManager**| Azure Resource Manager. | Outbound | No |No|
83
+
|**AzureResourceManager**| Azure Resource Manager. | Outbound | No |Yes|
84
84
|**AzureSentinel**| Microsoft Sentinel. | Inbound | Yes | Yes |
85
-
|**AzureSignalR**| Azure SignalR. | Outbound | No |No|
86
-
|**AzureSiteRecovery**| Azure Site Recovery.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory**, **AzureKeyVault**, **EventHub**,**GuestAndHybridManagement** and **Storage** tags. | Outbound | No |No|
85
+
|**AzureSignalR**| Azure SignalR. | Outbound | No |Yes|
86
+
|**AzureSiteRecovery**| Azure Site Recovery.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory**, **AzureKeyVault**, **EventHub**,**GuestAndHybridManagement** and **Storage** tags. | Outbound | No |Yes|
87
87
|**AzureSphere**| This tag or the IP addresses covered by this tag can be used to restrict access to Azure Sphere Security Services. | Both | No | Yes |
88
88
|**AzureSpringCloud**| Allow traffic to applications hosted in Azure Spring Apps. | Outbound | No | Yes |
89
89
|**AzureStack**| Azure Stack Bridge services. <br/> This tag represents the Azure Stack Bridge service endpoint per region. | Outbound | No | Yes |
90
90
|**AzureTrafficManager**| Azure Traffic Manager probe IP addresses.<br/><br/>For more information on Traffic Manager probe IP addresses, see [Azure Traffic Manager FAQ](../traffic-manager/traffic-manager-faqs.md). | Inbound | No | Yes |
91
-
|**AzureUpdateDelivery**| For accessing Windows Updates. <br/><br/>**Note**: This tag provides access to Windows Update metadata services. To successfully download updates, you must also enable the **AzureFrontDoor.FirstParty** service tag and configure outbound security rules with the protocol and port defined as follows: <ul><li>AzureUpdateDelivery: TCP, port 443</li><li>AzureFrontDoor.FirstParty: TCP, port 80</li></ul> | Outbound | No |No|
92
-
|**AzureWebPubSub**| AzureWebPubSub | Both | Yes |No|
91
+
|**AzureUpdateDelivery**| For accessing Windows Updates. <br/><br/>**Note**: This tag provides access to Windows Update metadata services. To successfully download updates, you must also enable the **AzureFrontDoor.FirstParty** service tag and configure outbound security rules with the protocol and port defined as follows: <ul><li>AzureUpdateDelivery: TCP, port 443</li><li>AzureFrontDoor.FirstParty: TCP, port 80</li></ul> | Outbound | No |Yes|
92
+
|**AzureWebPubSub**| AzureWebPubSub | Both | Yes |Yes|
93
93
|**BatchNodeManagement**| Management traffic for deployments dedicated to Azure Batch. | Both | Yes | Yes |
94
-
|**ChaosStudio**| Azure Chaos Studio. <br/><br/>**Note**: If you have enabled Application Insights integration on the Chaos Agent, the AzureMonitor tag is also required. | Both | Yes |No|
94
+
|**ChaosStudio**| Azure Chaos Studio. <br/><br/>**Note**: If you have enabled Application Insights integration on the Chaos Agent, the AzureMonitor tag is also required. | Both | Yes |Yes|
95
95
|**CognitiveServicesFrontend**| The address ranges for traffic for Cognitive Services frontend portals. | Both | No | Yes |
96
-
|**CognitiveServicesManagement**| The address ranges for traffic for Azure Cognitive Services. | Both | No |No|
97
-
|**DataFactory**| Azure Data Factory | Both | No |No|
98
-
|**DataFactoryManagement**| Management traffic for Azure Data Factory. | Outbound | No |No|
99
-
|**Dynamics365ForMarketingEmail**| The address ranges for the marketing email service of Dynamics 365. | Both | Yes |No|
96
+
|**CognitiveServicesManagement**| The address ranges for traffic for Azure Cognitive Services. | Both | No |Yes|
97
+
|**DataFactory**| Azure Data Factory | Both | No |Yes|
98
+
|**DataFactoryManagement**| Management traffic for Azure Data Factory. | Outbound | No |Yes|
99
+
|**Dynamics365ForMarketingEmail**| The address ranges for the marketing email service of Dynamics 365. | Both | Yes |Yes|
100
100
|**Dynamics365BusinessCentral**| This tag or the IP addresses covered by this tag can be used to restrict access from/to the Dynamics 365 Business Central Services. | Both | No | Yes |
101
101
|**EOPExternalPublishedIPs**| This tag represents the IP addresses used for Security & Compliance Center PowerShell. Refer to the [Connect to Security & Compliance Center PowerShell using the EXO V2 module for more details](/powershell/exchange/connect-to-scc-powershell). | Both | No | Yes |
|**Internet**| The IP address space that's outside the virtual network and reachable by the public internet.<br/><br/>The address range includes the [Azure-owned public IP address space](https://www.microsoft.com/download/details.aspx?id=56519). | Both | No | No |
107
-
|**LogicApps**| Logic Apps. | Both | No |No|
108
-
|**LogicAppsManagement**| Management traffic for Logic Apps. | Inbound | No |No|
107
+
|**LogicApps**| Logic Apps. | Both | No |Yes|
108
+
|**LogicAppsManagement**| Management traffic for Logic Apps. | Inbound | No |Yes|
109
109
|**Marketplace**| Represents the entire suite of Azure 'Commercial Marketplace Experiences' services. | Both | No | Yes |
110
-
|**M365ManagementActivityApi**| The Office 365 Management Activity API provides information about various user, admin, system, and policy actions and events from Office 365 and Azure Active Directory activity logs. Customers and partners can use this information to create new or enhance existing operations, security, and compliance-monitoring solutions for the enterprise.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory** tag. | Outbound | Yes |No|
111
-
|**M365ManagementActivityApiWebhook**| Notifications are sent to the configured webhook for a subscription as new content becomes available. | Inbound | Yes |No|
112
-
|**MicrosoftAzureFluidRelay**| This tag represents the IP addresses used for Azure Microsoft Fluid Relay Server. | Outbound | No |No|
113
-
|**MicrosoftCloudAppSecurity**| Microsoft Defender for Cloud Apps. | Outbound | No |No|
110
+
|**M365ManagementActivityApi**| The Office 365 Management Activity API provides information about various user, admin, system, and policy actions and events from Office 365 and Azure Active Directory activity logs. Customers and partners can use this information to create new or enhance existing operations, security, and compliance-monitoring solutions for the enterprise.<br/><br/>**Note**: This tag has a dependency on the **AzureActiveDirectory** tag. | Outbound | Yes |Yes|
111
+
|**M365ManagementActivityApiWebhook**| Notifications are sent to the configured webhook for a subscription as new content becomes available. | Inbound | Yes |Yes|
112
+
|**MicrosoftAzureFluidRelay**| This tag represents the IP addresses used for Azure Microsoft Fluid Relay Server. | Outbound | No |Yes|
113
+
|**MicrosoftCloudAppSecurity**| Microsoft Defender for Cloud Apps. | Outbound | No |Yes|
114
114
|**MicrosoftContainerRegistry**| Container registry for Microsoft container images. <br/><br/>**Note**: This tag has a dependency on the **AzureFrontDoor.FirstParty** tag. | Outbound | Yes | Yes |
115
115
|**MicrosoftDefenderForEndpoint**| Microsoft Defender for Endpoint <br/></br>**Please note this service tag is currently not available and in progress. We will update once it is ready for use.**| Both | No | Yes |
116
-
|**PowerBI**| Power BI. | Both | No |No|
116
+
|**PowerBI**| Power BI. | Both | No |Yes |
117
117
|**PowerPlatformInfra**| This tag represents the IP addresses used by the infrastructure to host Power Platform services. | Outbound | Yes | Yes |
118
118
|**PowerPlatformPlex**| This tag represents the IP addresses used by the infrastructure to host Power Platform extension execution on behalf of the customer. | Inbound | Yes | Yes |
119
-
|**PowerQueryOnline**| Power Query Online. | Both | No |No|
119
+
|**PowerQueryOnline**| Power Query Online. | Both | No |Yes|
120
120
|**ServiceBus**| Azure Service Bus traffic that uses the Premium service tier. | Outbound | Yes | Yes |
121
-
|**ServiceFabric**| Azure Service Fabric.<br/><br/>**Note**: This tag represents the Service Fabric service endpoint for control plane per region. This enables customers to perform management operations for their Service Fabric clusters from their VNET endpoint. (For example, https:// westus.servicefabric.azure.com). | Both | No |No|
121
+
|**ServiceFabric**| Azure Service Fabric.<br/><br/>**Note**: This tag represents the Service Fabric service endpoint for control plane per region. This enables customers to perform management operations for their Service Fabric clusters from their VNET endpoint. (For example, https:// westus.servicefabric.azure.com). | Both | No |Yes|
122
122
|**Sql**| Azure SQL Database, Azure Database for MySQL, Azure Database for PostgreSQL, Azure Database for MariaDB, and Azure Synapse Analytics.<br/><br/>**Note**: This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure SQL Database service, but not a specific SQL database or server. This tag doesn't apply to SQL managed instance. | Outbound | Yes | Yes |
123
123
|**SqlManagement**| Management traffic for SQL-dedicated deployments. | Both | No | Yes |
124
124
|**Storage**| Azure Storage. <br/><br/>**Note**: This tag represents the service, but not specific instances of the service. For example, the tag represents the Azure Storage service, but not a specific Azure Storage account. | Outbound | Yes | Yes |
125
-
|**StorageSyncService**| Storage Sync Service. | Both | No |No|
125
+
|**StorageSyncService**| Storage Sync Service. | Both | No |Yes|
126
126
|**WindowsAdminCenter**| Allow the Windows Admin Center backend service to communicate with customers' installation of Windows Admin Center. | Outbound | No | Yes |
127
127
|**WindowsVirtualDesktop**| Azure Virtual Desktop (formerly Windows Virtual Desktop). | Both | No | Yes |
128
128
|**VirtualNetwork**| The virtual network address space (all IP address ranges defined for the virtual network), all connected on-premises address spaces, [peered](virtual-network-peering-overview.md) virtual networks, virtual networks connected to a [virtual network gateway](../vpn-gateway/vpn-gateway-about-vpngateways.md?toc=%2fazure%2fvirtual-network%3ftoc.json), the [virtual IP address of the host](./network-security-groups-overview.md#azure-platform-considerations), and address prefixes used on [user-defined routes](virtual-networks-udr-overview.md). This tag might also contain default routes. | Both | No | No |
0 commit comments